plugin

404 Redirection Manager Vulnerabilities

3 known security issues reported for the 404 Redirection Manager WordPress plugin. Most recent disclosed Jun 15, 2026.

2 high 1 medium

Running 404 Redirection Manager on your site? Check whether your installed version is affected.

Scan your site free

404 SEO Redirection <= 1.0 - Unauthenticated SQL Injection

high

The 404 SEO Redirection plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL querie...

CVSS:
7.5
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Jun 15, 2026

CVE-2016-20071 on NVD →

404 SEO Redirection <= 1.3 - Cross-Site Request Forgery

high

The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site Scripting issues

CVSS:
8.8
Affected:
up to 1.3
Fixed in:
1.4
Disclosed:
Apr 16, 2021

CVE-2021-24324 on NVD →

404 SEO Redirection <= 1.3 - Reflected Cross-Site Scripting

medium

The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.

CVSS:
6.1
Affected:
up to 1.3
Fixed in:
1.4
Disclosed:
Apr 16, 2021

CVE-2021-24325 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database